Tell HN: "I don't care about cookies” extension bought by Avast, users jump ship
addons.mozilla.org
addons.mozilla.org
I think it would behoove Firefox and Chrome to change their policies around automatic extension upgrades in these scenarios: if an extension discloses a change in ownership, then upgrades should require user approval. If an extension fails to disclose a change in ownership, then users should be able to report it as malicious.
This is why people should be extremely cautious about becoming too attached to (or, worse, dependent on) any particular product or service. It can change ownership (and therefore policies) at any time.
I don't think he meant "deserves" in the literal sense.
Many seem to be well known because they're memorable, but some people assume they're well know because they contain wisdom.
E.g., "It's always darkest before dawn." or (the often misconstrued) "The exception proves the rule."
Here's a discussion about it[0].
First, here's the TL;DR:
SIEGEL: So far from being a pro-privacy quotation, if anything, it's a pro-taxation and pro-defense spending quotation.
WITTES: It is a quotation that defends the authority of a legislature to govern in the interests of collective security. It means, in context, not quite the opposite of what it's almost always quoted as saying but much closer to the opposite than to the thing that people think it means.
And here's the detail, discussed just before the TL;DR (I put in some paragraph breaks):
SIEGEL: And what was the context of this remark?
WITTES: He was writing about a tax dispute between the Pennsylvania General Assembly and the family of the Penns, the proprietary family of the Pennsylvania colony who ruled it from afar.
And the legislature was trying to tax the Penn family lands to pay for frontier defense during the French and Indian War.
And the Penn family kept instructing the governor to veto.
Franklin felt that this was a great affront to the ability of the legislature to govern. And so he actually meant purchase a little temporary safety very literally. The Penn family was trying to give a lump sum of money in exchange for the General Assembly's acknowledging that it did not have the authority to tax it.
[0] https://www.npr.org/2015/03/02/390245038/ben-franklins-famou...
At the very least, software needs to do what it used to do: make security updates separate from all other updates so users can just get the security bits.
Of course, in a world of walled gardens versus git repos, none of this very powerful use of ideas and computation can be done. I can't go to the Apple app store and easily cobble together my own franken app from what I find there. It's like a step back for innovation for our species when we set up these stupid profit seeking moats and gardens.
It seems less risky to continue automatic updates and just accept the possibility of malicious ownership change.
Hopefully that abuse will reach a point where the camels back breaks, and the pain of freeing yourself from vendor lock-in becomes worth it, prompting smart consumers and businesses in large numbers to use and support principled software projects through contributions of money, code and labor.
People can learn and have personal responsibility, but the companies would rather use such examples for leverage to keep them ignorant and corral them into putting nooses of control around their necks.
Except that this was due to a vulnerability in Windows which was fixed _after_ those worms ravaged the Windows users.
Plus if you look at the app store updates, most of the apps post nonsense in the release notes such as "fixed bugs", "Thank you for being a user of Lyft this update will make your experience even better!", or the worst kind:
"You know how sometimes you just become aware of how much tension you're holding in your body, then take a deep breath and slowly let it out? This update is like that. It's still Slack, just with a tiny bit less friction."
HOGWASH Slack, this update will likely cause friction! If only those people that write this crap got laid off, the world would be a tiny bit better :/
Maybe its time to declutter software that you don't control in your life just like how people declutter stuff. Every item is an additional tiny mental burden and the same goes for each closed source app installed on your phone. Maybe its better if we just forgo any "benefits" the app may provide and not bother anymore.
It's pretty clear Microsoft seems to think nobody cares (and to be honest they're probably right).
I think it's an unconscionable clause.
The loan servicer is more important --- some of them are terrible at their job and tend to misapply payments etc, causing extra work for the borrower.
That's not what causes loans to be transferred to others in the vast majority of cases.
(This is about as convenient, pleasant, and useful advice as the "just quit your job" advice).
Note that your first mortgage in CA is nonrecourse, but a refinanced mortgage is not nonrecourse (meaning the lender can come after you personally if you end up underwater).
The company matters just as much as the product or service.
Refinanced with a local CU and stayed with them ever since.
If in the US, I would be surprised to find out about prepayment penalties at all.
https://money.usnews.com/loans/mortgages/articles/what-is-a-...
> A lender cannot assess a prepayment penalty unless the penalty was included in the original terms of the loan.
> According to the Federal Register, Dodd-Frank Act provisions “generally prohibit prepayment penalties except for certain fixed-rate qualified mortgages where the penalties satisfy certain restrictions and the creditor has offered the consumer an alternative loan without such penalties.”
> For lenders that do charge these penalties, prepayment penalties cannot be imposed after the first three years of the loan term.
Are you sure? Whether a mortgage has prepayment penalties or not is one of the things that is specifically declared in every mortgage contract I've ever seen. They can't just change it after the fact.
WaMu pays after several phone calls. Then sends me a notice that my escrow account is $5000 in appears. So WaMu says that the 2000 was a mistake and I need to send that back, and that they are allowed to maintain an excess balance for taxes and insurance, so I need to send them another 3000 to bring the account current.
I refinanced with a different organization that week.
I was very happy to see them crater during the financial crisis.
For sure, there is an adverse impact to a borrower who is not well versed in how mortgages work, but in terms of financial agreements, but unfortunately, the US does not punish financial companies for negligence in customer service.
No, because if (as here) the original mortgage contract included an escrow account, that contract surely allowed the mortgage holder to demand money to keep the escrow balance where they want it to be.
So no, they didn't change the terms of the mortgage contract.
Not a great example because the terms of the mortgage are fixed by the original contract, regardless of who they sell it to later.
Whereas the extension (or any software) can radically change their terms (privacy policy, etc) in a single ugprade.
1. They usually mostly work in the background, don't need much interaction. It's almost like a built-in browser feature changing owners.
2. They are pretty difficult to find a business model for - as opposed to SaaS stuff and mobile apps, which people pay for rather commonly. So the choice is to a) Make no money b) Ask for donations (seems to only work if it's somewhat obnoxious) c) Make money in some creative (often shady) way d) Sell the thing.
AFAIK, it is not easy (or maybe not possible) to opt out of extensions updates.
The entire purpose of trademarks is to protect consumers. Being able to use them to mislead consumers is the opposite of that.
Instead, this is the kind of thing that needs to be solved on the policy level: Google and Mozilla have an interest in maintaining high-quality extension ecosystems, and ought to take a dim view of these kinds of ownership transfers.
Not really, no. The software space was much, much richer and you could get along extremely well without using much software from the big guys.
Today we have the illusion of speaking globally but have been gatekept out by a handful of companies.
I don't do automatic updates and actively prevent that from happening. Automatic updates are a plague that means you can't rely on the software anymore, if for no other reason than an update may (and likely will, eventually) remove or otherwise bork the very aspect that made it valuable to you.
But I'm a weirdo and take care to ensure that I actually own and control the software I use. I see people getting burned because they're at the mercy of a company all too often.
I've switched to FreeBSD and things mostly stay working, but I've already seen steps in the direction that Linux has gone, so I fear it's just a matter of time.
Plus, a lot of these server dependencies are added to create that dependency and the software would be better off without them anyway.
Remember when Java and MySQL weren't owned by Oracle?
I do.
2000-2005, the biggest automatic updates that consumers had to deal with were Windows (Office, OS, etc) updates and games. Valve's Steam, which had come into prevalence (notably Counterstrike:Source), World of Warcraft, etc.
By 2008 (Google Chrome), automatic updates were common. I would say the ship had sailed by 2005. Yes, this is 1 full generation ago.
On several different SaaS softwares used at my employer I have found myself asking if they have entire teams of highly compensated UX professionals and graphics designers who justify their continued employment by changing the interface every 3 months by just enough to annoy me after I finally remap my brain to the latest locations of the tools and buttons.
For example, I doubt that Debian would would take an update from an upstream that is detrimental to their users. They would follow a friendlier fork first. Debian maintainers follow their users' interests first.
(I'm a Debian Developer)
Edit: and that means you can generally trust automatic updates on Debian.
I'd much rather have my applications run unrestricted but vetted and if neccessary patched by a trusted third party (the distro) than lock whatever dark patters and anti-features developers come up with into a box ... where it still has access to all interactions with that box.
In particular, I wouldn't trust a Firefox distributed by Mozilla without oversight but I still use the Firefox packaged by my distro.
But in the case of something like Firefox, distros are barely vetting anything, and are reluctant to patch because such patching rapidly becomes unmaintainable. Most dependencies don't end up unbundled, either. So distribution Firefox packages are really external packages in distribution package clothing, more so than any other package, really.
This is why I want sandboxing anyway - because I understand the limits of what is practical.
And sandboxing and limiting interaction through well-defined interfaces is better for security anyway, because security vulnerabilities happen regardless, and sandboxing does provide some level of mitigation.
Finally, the distribution packaging model is insufficient for many users. Even if you are fine with it, most users want something newer than their distribution release, and we can see that they are prepared to give up security and system stability for it. This is a real need for these users, and sandboxed third party packaging mechanisms provide a real solution for them, even if you can manage without.
Any time a company has physical access to your data, and says they will not sell it, they are lying (unless it is privately held, and never takes on debt / pays after delivery).
In particular, EULAs and other contracts do not protect your information in the above situations, since debt and shareholder obligations generally come before customer obligations, and the data is considered an asset.
As other commenters have pointed out, it doesn't apply as much to actual physical products.
So this leads to reason, should any of this be accepted as the norm?
They would just change ownership and keep that a secret from the world. Avast would 'hire' the dev of this extension, and provide him with more engineers and ideas of features to implement.
I have received a few solicitations to sell apps that had not been updated in a while (they were still good, but hadn't required an update).
I suspect the buyer would repackage the app with some "extra spices," either advertising, or malware, and would count on the auto-update to force it onto users' devices.
I declined. I remove moribund apps. I've written over 20 but only have a few on the store.
Good on you!
1. Open application menu
2. Add-ons
3. Extensions
4. click gear
5. uncheck Update add-ons automatically
doesn't seem like it:
> I can be a passive user of an excellent extension for years, and wake up one morning to discover that my browser has (silently!) upgraded the extension
you want to roll the dice with automatic updates, you have only yourself to blame when they break something you care about. people always scream BUT MUH SECURITY, and at the same time ignore every other awful change that is rammed through automatic updates. pick your poison.
I don’t want to “roll the dice.” There is a significant difference in user model between trusting a single identity to provide updates automatically, and naively trusting updates that come from a new identity.
In the context of web extensions, not auto-updating is frequently not an option: web extensions are part of an arms race between users and websites, with the extensions continually playing catch-up.
just because you might find one choice extremely distasteful, doesn't mean the option ceases to exist. so I will say again, pick your poison. you opt in, or fail to opt out of automatic updates, then you accept anything that might happen because of that.
It really makes me wonder if there's a way to formalize a system of verification, trust, vouching, etc. not just for extensions but for source-viewable software in general, version by version, diff by diff.
Volunteers actually inspect an extension's JavaScript to check for anything potentially malicious (is it reporting on user activity etc.), they vouch for each other, and you select some core single individual or group to trust (or majority-vote or something), and then only allow software on your system that is vouched for. Nothing ever gets upgraded until it passes.
"Vouching" can form that kind of trusted intermediate, but probably not without grinding an ordinary speedy update process to a near halt. That's probably a worse outcome than just having the pre-existing authority (i.e., Mozilla or Google) establish an enforceable policy around what constitutes an acceptable (or acceptably transparent) update.
The solution seems to be much more clearly in the realm of things like crev: https://github.com/crev-dev/cargo-crev/
Wherein users can get a clear picture of what dependencies are used in the full chain, and how they have been independently reviewed for security and privacy. That's the real solution for the future. A quick score that is available upon display everytime you upgrade, with large warnings for anything above a certain threshold.
MV3 is the reason I switched back hesitantly to Firefox.
Change just happens, you need to be on top of it, to not miss things like this. This isn't going to have a technological solution.
1. There is a "Write a review" button, but you cannot leave a review.
2. There is no owner listed on the extension page. Only the text "Featured", and some kind of rosette certificate badge.
https://chrome.google.com/webstore/detail/i-dont-care-about-...
So I just refuse and skip all updates, but yeah that's not an option with extensions afaik.
I have couple extensions I've made. Most have couple hundred weekly users, but one has few thousand and I have gotten emails about adding ad and search redirect code for some money. If I was in bad financial situation or just didn't care, I could have just added the code without anyone really knowing.
Still, it could be not disclosing it in such cases and live with it in a gray zone.
I think that is actually normal overall, but the real fast riches are of course in the big buyout.
I don’t blame the companies, though I’ve taken a bootstrapped strategy because I didn’t want to get stuck on the VC treadmill.
It's called "being a for-profit company."
Many people work for places and sell their soul to them, accepting the evil they push - e.g. Google
It's not unique to solo devs. Unless you work for a morally sound employer, and only interact with morally sound companies, throwing shade like that just means the boot will fit on you too.
Since I care about a fast efficient web experience far more than I care about leaving digital footprints around, I choose the extension that says yes to everything.
Asking me if I'd like to allow various cookies is by far the least important part of the problem. Relying in the cooperative efforts of site owners? Really?
It's not just that - some services are literally unrenderable without cookies! (Fewer these days at least).
If someone says a cookie is non-essential and rejecting it results in their site not working that’s on them - a human might manually choose to reject it, it’d be the same end result.
(Yes, I manually click or click click for every website. Also I don't think that EU "broke the internet", rather they made me painfully aware that every f.in website uses cookies and other tracking methods just to give my browsing history to ~300 total random company for no reason.)
https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat... (Firefox)
https://chrome.google.com/webstore/detail/consent-o-matic/md... (Chrome)
https://consentomatic.au.dk/ (Official site)
When it's needed for the website to work properly, it will automatically accept the cookie policy for you (sometimes it will accept all and sometimes only necessary cookie categories, depending on what's easier to do).
It's broken though, and messes up YouTube by persisting the cookie interstitial in an invisible overlay, making the interface unusable. This is why these types of addons have so many new versions: they have to constantly watch for changes in the JS/CSS of cookie banners.
Thank god we have community maintained alternative forks[0]
[0] https://addons.mozilla.org/en-US/firefox/addon/istilldontcar...
> It is very wrong for the extension to change ownership without warning the user about it. I trusted the original developer of this extension, but i do not trust Avast.
I don't see the logic here. Unless Avast had threatened him, I wouldn't trust neither of the parties. How do you trust someone that sells their extension to someone you don't trust and still trust them?
I can imagine a number of scenarios, but I'm unfamiliar with this particular case. Could someone elaborate on what actually happened or what is the danger?
it's not something any company would want to be exempted from. companies like this.
cookiebanners.ui.desktop.enabled = true
It will appear in Settings / Privacy / Cookie Banner Reduction
It's interesting how brand perception changes over time.
Just looked up what Avast looked like in the 2000's. The aftermarket car stereo GUI[1] just brought back memories I forgot about :P
[1]http://assets.oldversion.s3.amazonaws.com/images/avast-free-...
Notable examples:
- Resolution test (allowed to change browser size so you can make perfect screenshots and videos), now needs full tab content access because "Facebook upload functionality" - [1]
- Awesome screenshots (it was perfect extension which allowed to take screenshots and videos), now it is called "Awesome ChatGPT Screenshot & Screen Recorder"
- [1] https://chrome.google.com/webstore/detail/resolution-test/id... - [2] https://chrome.google.com/webstore/detail/awesome-chatgpt-sc...
Does this have anything to do with Chrome's new extension API nerfing ad blockers?
It's quite good at doing that.
Sounds like I might need to investigate consent as well...but the "pain identification" isn't going to work the same way. With the consent management, I'll probably end up having to do a lot of per-site work...which kind of defeats the purpose. Sigh. Guess I'll find out, on a sufficiently annoyed weekend.
Yes, for Google Calendar and Slack.
If we want complicated apps to be available on the web we need complicated browsers. The competition situation is troublesome but nothing compared to the complete monopolies Apple and Play store has.
Non technical, average users hit "yes" in nearly every case, usually ending with opt in to fake tech support popups and porn spam.
The way I see it, it would make sense to explicitly whitelist a website (e.g. Gmail or Webex) in a similar manner to installing an app, and all the other websites don't even get to beg for these permissions.
It wasn't the browsers, it's EU regulation. Most sites choose to operate legally in Europe, so the banner is displayed. Devs don't care about making it so only European users see it, so the rest of the world must suffer too.
Having this within browser in theory should solve the issue of consent but I frankly doubt that such permanent solution would agree with Microsoft or Google goals. Mozilla - perhaps would roll this but I wouldn't have any big hopes.
And yes, I did intentionally clicked "yes" thinking no 3rd-party cookies will be saved but that was in the early days of GDPR. There are sites that allow users to disable 3rd-party "legitimate interests" cookies under modal submenus and some only show em in enabled state without any options.
I gradually found that the remote features in the vein of "Find my Device" were trash and never worked. I could never contact my Android tablet with the website, or make any meaningful GPS search for it. I didn't once try factory-wiping it, but I basically assumed that it would fail in the very moment I needed it most. Fortunately, I never did require these features, and they stayed resolutely broken.
Avast! changed something about the service and I decided it was totally not worth having anymore, so I canceled and uninstalled, then they charged me again (Google Play Store). I was able to go after them and procure a refund, but I was not happy about the casual consumer abuse after a malfunctioning product.
Avast! is HQ'd in the Czech Republic, and I have mixed feelings about my cybersecurity entrusted to such a faraway foreign land that's close to the whole Eastern Bloc, so good riddance, and I guess I'll use Malwarebytes next time.
Americans buying Avast is when Avast became this bad.
Interestingly, I as a Czech have very mixed feeling towards security of anything coming from a big country such as the US. Big countries with a big national security apparatus can strongarm their businesses into all sorts of backdoors more efficiently.
If anything, the former Eastern Bloc is sorta culturally more wary about trusting governments and giving them intrusive powers. We were burnt thoroughly by the old governments being too powerful. Westerners often strike us as being naive with regard to their own political class, and too willing to give up their personal autonomy if a suitable boogeyman is invoked.
Also, I would accept one cookie, which stores that I don't accept other cookies.
But oh no, now there's a big corp that owns the extension! And they might be survellied!
The name itself screams apathy here. My understanding from a while back was that the tool actively accepted a wide variety of cookies, and did nothing to minimize selections. I don't know if this is a misinterpretation, or if the project has changed to actively start caring somewhat about cookies.
Whereas the extension has full access to not only your browsing history, but also every password, every credit card number ever typed, etc.
Cookies are a minor privacy problem compared to an 'access all sites' chrome extension.
https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies/...
https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies/...
Not sure what's bad about the code. I mean, the variable names could be more enlightening, and there are no comments, but I don't think it qualifies as "spaghetti".